In applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to observe the users password on a secondary display due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-179725730
The product initializes or sets a resource with a default that is intended to be changed by the product’s installer, administrator, or maintainer, but the default is not secure.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Android | 10.0 (including) | 10.0 (including) | |
| Android | 11.0 (including) | 11.0 (including) | |
| Android | 12.0 (including) | 12.0 (including) | |
| Android | 13.0 (including) | 13.0 (including) |